CVE-2019-14656
08.10.2019, 13:15
Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP.Enginsight
Vendor | Product | Version |
---|---|---|
yeahlink | vp59_firmware | 𝑥 ≤ 2019-08-04 |
yeahlink | t49g_firmware | 𝑥 ≤ 2019-08-04 |
yeahlink | t58v_firmware | 𝑥 ≤ 2019-08-04 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration